A vulnerability identified as problematic has been detected in cvat-ai CVAT up to 2.66.0. This issue affects some unknown processing of the component Annotation Guide Assets. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-65986. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.